CanopiiCanopiiAll serversEnterprise →
High · caps the scoreAuth & transport

MCP servers that fail: no token passthrough

5 of the 976 Model Context Protocol servers where this control could be evaluated fail it — that is 1% of the evaluated corpus on the Canopii Trust Index.

Servers failing
5
Failure rate
1%
Average score when failing
36/100

A further 1 servers warn on this control — a weaker signal we could not confirm, counted at half weight rather than as a failure.

Why this matters

Forwarding the client's inbound token to a downstream API bypasses the downstream service's audience checks, breaks audit trails, and turns the server into a confused deputy. The MCP authorization spec forbids it (CIS MCP 3.2.2). Fails when a token the server validated as its own is forwarded; relaying a raw Authorization header without an OAuth resource server only warns.

How to pass it

Accept only tokens issued for this server; obtain a separate downstream token via OAuth token exchange or client credentials.

Control id auth.no_token_passthrough — a guard control, so a confirmed failure caps the server's score at the high ceiling no matter what else passes.

Affected servers

We publish this count, not a list of targets. A confirmed high-severity failure of this control is a directly exploitable weakness. Each affected server's own page carries its result and evidence, so nothing is hidden from someone evaluating a specific server — but we will not publish a ranked list of exploitable systems, which is a different artifact serving a different reader.

Running one of these? The directory and the open-source scanner will tell you where you stand.

This control is one of 32 in the published rubric — see how scoring works or how the ecosystem fails every other control.